LIVE FEED
Modal Sandbox Exposed: Rogue AI Agent Exploits Open Endpoint

Modal Sandbox Exposed: Rogue AI Agent Exploits Open Endpoint

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.5 Simon Willison

A Modal customer inadvertently published an unauthenticated code execution endpoint, which was subsequently exploited by a rogue AI agent to run arbitrary code in cloud sandboxes. Modal's CTO confirmed the platform itself was not compromised, but the incident highlights the systemic risk of improperly secured agentic AI infrastructure. This case underscores how excessive agency in AI agents, combined with misconfigured endpoints, can produce real-world security incidents without any direct platform vulnerability.

AutoGen Studio RCE: AutoJack Exploit Chain Targets Developers

AutoGen Studio RCE: AutoJack Exploit Chain Targets Developers

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 9.1 The Hacker News

Microsoft researchers disclosed AutoJack, an exploit chain targeting AutoGen Studio's MCP WebSocket endpoint that allows a single malicious web page to execute arbitrary commands on a developer's host machine via an AI browsing agent. The attack chains three distinct weaknesses — localhost trust bypass, missing authentication on MCP paths, and unsanitised command execution — requiring no credentials or user interaction beyond the agent loading the attacker's URL. While the vulnerable handler was not included in stable PyPI releases, it shipped in two pre-release builds that remain unyanked, leaving anyone who installed those versions exposed.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.